[ LEAVEPILOT · LEGAL ]
Superseded version
This version is no longer in force. It stays published because it still binds the organisations that accepted it while it was current. The version in force is dpa-2026-08-21-v5.1.
Courtesy translation
This translation is provided to make the document easier to read. The text that binds the parties is the Italian one: in the event of any discrepancy the original prevails, and it is its fingerprint that is recorded when the agreement is accepted.
- Version
- dpa-2026-08-18-v5
- In force since
- 18 August 2026
- SHA-256 fingerprint of the text
- 553f90e903d40866ddef9f1eda6c1fd616d7461932dc33e4adbbe06cbfc3b63b
- Verifiable against a copy of the text with shasum -a 256 content/legal/dpa-2026-08-18-v5.en.md. If the fingerprint matches, the text has not been altered since publication.
Data processing agreement
Article 28 of Regulation (EU) 2016/679 Service: LeavePilot Template version: 5.0 of 18 August 2026
The Italian version prevails / La versione italiana fa fede.
Parties
This Agreement is entered into between:
MAXYMIZE BUSINESS DI GIURASTANTE ROMANO MAXIMILIAN, with registered office at Via Delle Valli 57, 66010 Canosa Sannita (CH), Italy, tax code and VAT no. IT02747200695, hereinafter the Processor;
and
the organisation that accepts this Agreement through the LeavePilot platform, hereinafter the Controller, identified by the name and the details entered at registration and by the particulars of the acceptance recorded by the Processor under article 15.
Whereas
a) the Controller uses the LeavePilot service to manage requests for holidays, hourly leave and remote working made by its employees and collaborators;
b) the Processor developed the service, maintains it and manages its infrastructure, processing on the Controller's behalf the personal data necessary for it to operate;
c) the parties intend to govern that processing under article 28 of Regulation (EU) 2016/679, hereinafter the Regulation;
d) this Agreement is concluded in electronic form under article 28(9) of the Regulation, which expressly allows that form, by means of the acceptance given by the Controller in accordance with article 15;
the parties agree as follows.
Article 1 — Subject matter and roles
1.1 The Controller determines the purposes and means of the processing of its employees' and collaborators' data and appoints the Processor for the operations described in Annex A.
1.2 The Processor processes the data solely for the provision of the service and not for its own purposes. In particular it does not use the Controller's data to develop or improve products, for independent statistical or commercial purposes, or to train artificial intelligence models.
1.3 There is one exception, and only one: the collection of technical events described in Annex D, namely events about how the platform is functioning, containing no names, no email addresses and no absence details, which the Processor collects for its own diagnostic and security purposes and in respect of which it acts as an independent controller, not as the Controller's processor. It does not concern the data the Controller enters into the platform.
1.4 The Processor declares that it provides sufficient guarantees to implement appropriate technical and organisational measures, under article 28(1) of the Regulation.
Article 2 — Duration
2.1 This agreement takes effect from the date of conclusion and lasts for the whole term of the service contract, terminating automatically with it.
2.2 Confidentiality obligations remain in force after termination.
Article 3 — Documented instructions
3.1 The Processor processes the data only on documented instructions from the Controller. This agreement, the service contract and the instructions for use supplied to the Controller constitute documented instructions.
3.2 Where the Processor is required to carry out processing by a legal obligation, it informs the Controller before doing so, unless the law prohibits this on important grounds of public interest.
3.3 The Processor immediately informs the Controller if it considers that an instruction received infringes the Regulation or other data protection provisions.
Article 4 — Confidentiality
4.1 The persons authorised to process the data are bound by a duty of confidentiality, whether contractual or statutory.
4.2 As at the date of conclusion, the perimeter of authorised persons coincides with the owner of the sole trader business that is the Processor. Any extension is notified to the Controller, and new persons are authorised and instructed before they access any data.
Article 5 — Security measures
5.1 The Processor implements the technical and organisational measures described in Annex B, appropriate to the risk under article 32 of the Regulation.
5.2 The measures may be updated provided the level of security is not reduced. Significant changes are notified to the Controller.
Article 6 — Sub-processors
6.1 The Controller authorises the use of the sub-processors listed in Annex C, which states for each of them the name, the function performed, the place of processing and the legal basis of any transfer outside the European Economic Area.
6.2 The Processor notifies the Controller at least thirty days in advance of any intention to add or replace a sub-processor. Within that period the Controller may object on reasonable and documented grounds; if it objects, the parties look for an alternative solution and, where none is possible, the Controller may withdraw from the service contract at no cost.
6.3 The Processor imposes on each sub-processor, by contract, data protection obligations no less onerous than those in this agreement, and remains liable to the Controller for its sub-processors' failures.
6.4 The sub-processor that produces the report commentary text is a single, pre-determined one. The service uses no routing intermediaries and no fallback chains towards alternative providers: if the provider named in Annex C is unavailable, the report is produced without the commentary section.
Article 7 — Rights of data subjects
7.1 The Processor assists the Controller, by appropriate technical and organisational measures, in responding to requests from data subjects exercising their rights.
7.2 A Processor that receives a request directly from a data subject does not act on it independently and forwards it to the Controller within five working days.
Article 8 — Assistance to the Controller
8.1 The Processor assists the Controller in ensuring compliance with the obligations under articles 32 to 36 of the Regulation, taking into account the nature of the processing and the information available to it.
8.2 On request, the Processor supplies the technical information needed for a data protection impact assessment and for the assessment of the obligations laid down by article 4 of Italian law 300/1970 and article 1-bis of Italian legislative decree 152/1997.
Article 9 — Personal data breaches
9.1 The Processor informs the Controller without undue delay and in any event within twenty-four hours of becoming aware of a personal data breach.
9.2 The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed.
9.3 Notifications to the supervisory authority and to data subjects remain the Controller's responsibility.
Article 10 — Deletion or return
10.1 On termination of the service, at the Controller's choice, the Processor deletes the data or returns it in a structured, commonly used and machine-readable format.
10.2 The Controller expresses that choice within thirty days of termination. Absent any indication, the Processor proceeds to delete the data after a further notice.
10.3 Backups are deleted according to the ordinary rotation cycle described in Annex B.
Article 11 — Demonstrating compliance
11.1 The Processor makes available to the Controller the information necessary to demonstrate compliance with the obligations of this agreement.
11.2 The Controller may carry out audits, directly or through a third party bound by confidentiality, on at least fifteen days' notice, during working hours, no more than once a year except following a breach. Audits must not compromise the security of the service's other customers.
Article 12 — Transfers outside the European Economic Area
12.1 Any transfers are set out in Annex C together with their legal basis under Chapter V of the Regulation.
12.2 The Processor makes no further transfers without first informing the Controller and without having identified an appropriate legal basis.
12.3 None of the suppliers listed in Annex C may receive the data covered by this Agreement on the basis of the EU-U.S. Data Privacy Framework adequacy decision: those suppliers' certifications cover non-HR data only. Transfers therefore take place on the basis of the standard contractual clauses, provided for in all the agreements with the suppliers. The verification is described in Annex C.
Article 13 — Liability
13.1 Each party is liable for the damage caused by its own breach, in accordance with article 82 of the Regulation.
13.2 Any limitations of liability set out in the service contract do not apply to the obligations under this agreement, to the extent that this is mandatory by law.
Article 14 — Governing law and jurisdiction
14.1 This agreement is governed by Italian law.
14.2 Any dispute falls within the jurisdiction indicated in the Terms of Service.
Article 15 — Conclusion and evidence of the Agreement
15.1 This Agreement is concluded by the acceptance given by the Controller through the platform, at the same time as the acceptance of the Terms of Service, under article 28(9) of the Regulation.
15.2 The Processor records and retains, for each acceptance: the identifier of the organisation, the identifier and email address of the person who accepted, the date and time, the version identifier and the cryptographic fingerprint of the text accepted. That record constitutes evidence of the conclusion of the Agreement and of its content.
15.3 The Controller may at any time download from the administration area an attestation setting out the text of the Agreement in the version accepted and the particulars of its own acceptance.
15.4 The record referred to in point 15.2 is retained for the duration of the relationship and for the subsequent limitation period, including where the account is deleted, limited to the data listed there.
15.5 A Controller that, for its own internal procedures, requires a signed copy of the Agreement may request one from the Processor. Signature is not a condition of effectiveness of the Agreement, which is concluded under point 15.1.
Annex A — Description of the processing
Subject matter: management of absence requests made by the Controller's employees and collaborators.
Nature and purpose: collection, recording, storage, consultation, processing, extraction and export of the data needed to manage holidays, hourly leave and remote working, to produce reports and to export data for payroll processing.
Duration: for the term of the service contract.
Categories of data subjects: the Controller's employees and collaborators; persons designated as approvers or administrators.
Categories of personal data:
- identification and contact data: first name, surname, email address;
- employment-related data: department or place of assignment, holiday and leave allowance, balances;
- absence-related data: start and end dates, type of absence, status of the request, any note entered by the requester;
- access data and operations log.
Special categories of data, article 9 of the Regulation: the service allows sick leave to be recorded. The mere indication of the type of absence may constitute health data. The Controller decides whether to enable that type; where enabled, the Processor applies the enhanced measures set out in Annex B and the legal basis for the processing is identified by the Controller under article 9(2)(b) of the Regulation.
Processing by artificial intelligence: the report commentary text is produced by a language model that receives aggregate figures only. It receives no names, identifiers or email addresses, no data relating to individual employees and no individual values. Departments of fewer than three people are not transmitted as a separate entry. How it works is described in the instructions for use.
Annex B — Technical and organisational measures
Separation of data between customers. Membership of the organisation is a structural condition of access to the data, not a filter applied case by case: a request that does not correctly identify the organisation returns no data.
Access control. Individual authentication; role-differentiated permissions; no shared accounts.
Encryption. Data in transit protected with TLS; data at rest encrypted as guaranteed by the infrastructure suppliers listed in Annex C.
Minimisation towards the model provider. The data sent to the language model is aggregated and free of identifying elements, with a confidentiality threshold of three people for groups. The text produced is subjected to an automatic check that discards it if it contains a name present in the data, a reference to personal states, or a recommendation: discarded text is neither corrected nor regenerated.
Traceability. Every generation of a commentary is recorded with the date and time, the organisation, the period requested, the model used, the version of the instructions and the outcome. The register does not contain the content of the report. Every report containing a generated commentary records in its metadata the model and the version of the instructions.
Backups. Backups managed by the database infrastructure supplier according to the cycle indicated in Annex C, with automatic rotation.
Operations log. Operations on the data are logged. The logs contain no employee names.
Retention. The data entered into the platform is retained for the term of the contract. For the other elements the periods are as follows.
Generated reports. Not retained. The document is produced at the moment it is requested and delivered to the person who requested it; the service keeps no copy, neither on its own systems nor at its suppliers. There is therefore no retention period, because there is no copy to delete.
Register of commentary generations. Twenty-four months from generation. The register serves to reconstruct how a disputed commentary was produced and contains the organisation, the moment, the period requested, the provider, the model, the version of the instructions and the outcome: it contains neither the text produced nor any data relating to a person. It resides on a database separate from those of the organisations, and expired rows are deleted by an automatic procedure that runs on the first of each month.
Register of administrative operations. Retained for the term of the contract, inside the organisation's own database, and deleted together with it. No shorter period is provided for: the register serves to reconstruct who did what to the Controller's data, and deleting it early would deprive the Controller itself of that possibility.
Technical logs of the infrastructure suppliers. Access, errors and function execution are retained by the suppliers listed in Annex C according to their own policies, and not by the Processor. For the supplier that hosts the application the declared retention is at least twenty-four hours, extended to seven days on some plans. The Processor neither extends that period nor keeps a copy.
Change management. The instructions used by the model are versioned in the source code. Every change is handled as a release and notified to the Controller.
Annex C — Authorised sub-processors
| Name | Function | Place of processing | Basis for the transfer |
|---|---|---|---|
| Databricks, Inc., through Neon, LLC | database hosting and management: all data entered into the platform, including that of the Controller's employees | European Union, eu-central-1 region (Frankfurt). Each organisation has its own separate database | Standard contractual clauses of the European Union, incorporated into the supplier's agreement, which at article 8.1 states them as the basis of every restricted transfer. The supplier participates in the EU-U.S. Data Privacy Framework, but its certification covers non-HR data only: it is therefore not a usable basis for the data covered by this Agreement. Sources: the supplier's data processing agreement and its public profile on the programme list, consulted on 18 August 2026 |
| Netlify, Inc. | hosting of the application and of the functions that process requests; delivery of static content; storage of the sick leave certificates uploaded by the Controller's employees, kept encrypted with the AES 256-bit algorithm | United States, the supplier's default region for function execution; content delivery network with a global presence | Standard contractual clauses of the European Union (modules 2 and 3), applicable by express provision of article 14.3 of the supplier's agreement where the transfer is not covered by the Framework. The supplier's certification covers non-HR data only and therefore does not cover this transfer. Sources: the supplier's data processing agreement of 9 June 2026 and its public profile on the programme list, consulted on 18 August 2026 |
| Plus Five Five, Inc., trading as Resend | sending service communications to the Controller's employees: the recipient's name and email address and the content of the communication. Not used where the Controller configures its own email provider | United States | Standard contractual clauses of the European Union, which the supplier's agreement states as the basis for transfers outside the European Economic Area and which are deemed entered into upon acceptance of the terms. The supplier's certification under the Framework covers non-HR data only and therefore does not cover this transfer. Sources: the supplier's data processing agreement of 31 December 2025 and its public profile on the programme list, consulted on 18 August 2026 |
| Anthropic PBC | production of the report commentary text, on aggregated data free of identifying elements | United States, called directly with no intermediaries | Standard contractual clauses of the European Union (modules 2 and 3), automatically incorporated into the supplier's commercial terms. The supplier does not participate in the Framework: the clauses are the sole basis, and there is no coverage check to perform. Source: the supplier's data processing agreement in force since 24 February 2025, consulted on 18 August 2026 |
Note on the basis for transfers. Three of the four suppliers participate in the EU-U.S. Data Privacy Framework, and none of the three may receive this data on that basis. The reason is that their certification is limited to non-HR data, whereas the data processed by this service is collected entirely in the employment context. The European Data Protection Board requires the exporter to ascertain this before the transfer, not to presume it: the verification was carried out on 18 August 2026 on the programme's public list, with a negative outcome for all three. This does not reduce the level of protection, because each agreement provides for the standard contractual clauses precisely for this case, and it is the reason why this Annex states them as the operative basis rather than as a subsidiary remedy.
Note on diagnostic events. The supplier that collects the technical events does not appear in this list because it does not process data on behalf of the Controller: it processes it on behalf of the Processor, who is an independent controller for that processing. It is described in Annex D, where the difference in role is explained in full.
Note on data separation. Each organisation's database is distinct from the others'. Deleting an organisation entails deleting its database.
Note on the language model provider. Up to version 2.29.8 of the service the call to the model went through a routing intermediary that could serve it with different providers. Since version 2.29.9 the call goes directly to a single, pre-determined provider with no fallback alternatives: that is the condition that makes this list truthful and verifiable, as required by article 28(2) of the Regulation.
Annex D — Technical events collected by the Processor
This annex is not part of the appointment. It describes a separate processing operation, in which the Processor acts as an independent controller, and it is here for transparency: the Controller must know what leaves the platform even when it does not leave on its behalf.
Why the role is different
No Controller asks LeavePilot to collect diagnostic events. The purposes and means of that collection are determined by the Processor, in order to understand where the service breaks and to recognise anomalous access. Whoever determines purposes and means is a controller: calling the supplier that receives them a "sub-processor" would be a convenient and false description.
What is collected
Events about how the platform is functioning: pages opened, actions taken, errors, response times. A module strips names, email addresses and absence details before sending.
The technical identifiers of user, organisation and session remain. This is pseudonymised data, not anonymous data: recital 26 of the Regulation is explicit that pseudonymisation does not take data outside the scope of the Regulation, and that is why this annex exists instead of simply declaring that no personal data is collected.
Not collected: the content of absence requests, sick leave certificates, notes, addresses, contact details.
Legal basis and information
The processing rests on the Processor's legitimate interest in keeping the service working and secure, under article 6(1)(f) of the Regulation. Data subjects are informed of it by the service's privacy notice, which also states the rights that may be exercised and how to object.
Supplier
| Name | Function | Place of processing | Basis for the transfer |
|---|---|---|---|
| PostHog Inc. | collection and storage of the technical events, as processor of the Processor | the supplier's European instance | standard contractual clauses of the European Union, module 2, signed between the parties on 18 August 2026. The supplier also participates in the EU-U.S. Data Privacy Framework with a certification that extends to HR data as well |
It is the only one of the service's suppliers whose certification under the Framework covers both categories of data, and the only one with which the agreement was signed and countersigned rather than concluded by acceptance of terms.
Consequence for the Controller
None, in terms of obligations: the Controller is not answerable for this processing, which is not carried out on its behalf. Should it nevertheless wish its employees not to be included in the collection of technical events, it may request that this be switched off for its own organisation by writing to the Processor.
All published versions
Every version stays at its own address, with its own text and its own fingerprint, even once superseded. It is there for whoever is bound by an earlier version and needs to read back exactly that one.
- dpa-2026-08-21-v5.121 August 2026in force
- dpa-2026-08-18-v518 August 2026
- dpa-2026-08-18-v418 August 2026
- dpa-2026-08-12-v312 August 2026
- dpa-2026-08-12-v212 August 2026
- dpa-2026-08-12-v112 August 2026